Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7127
HistoryJul 23, 2018 - 8:32 a.m.

XML External Entity (XXE)

2018-07-2308:32:08
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

EPSS

0.004

Percentile

74.9%

Jasig CAS Client is vulnerable to XML External Entity (XXE) injection. The attacker can trigger the attack by sending malicious XML data because it does not prevent loading malicious XML data via java/org/jasig/cas/util/SamlUtils.java in Jasig CAS server when Google Accounts Integration is on.

EPSS

0.004

Percentile

74.9%

Related for VERACODE:7127